Deploying AI On-prem? Now Secure It!

Wednesday, August 20, 2025
12:00 PM - 12:30 PM
AI Risk Summit Track 1 (Salon I)

About This Session

AI is no longer experimental, it’s operational. Enterprises are deploying AI models into production applications where they interact with sensitive data, call backend systems, and make real-world decisions. The use cases might be new, but the risks are familiar. Privilege escalation, supply chain compromise, data exfiltration, and unauthorized execution now flow through a different path: the prompt.
In this session, we’ll walk through how on-prem and private AI deployments actually work, from user input to inference to tool execution. We’ll dissect the modern AI stack, illustrate where risks accumulate, and show how those risks resemble what we've long dealt with in containerized applications.
Key topics covered:
• How AI workloads show up in enterprise applications
• What a production AI transaction looks like under the hood
• Where traditional controls (SAST, DAST, firewalling) fail
• How AI risks like prompt injections can lead to familiar attack paths
• The security capabilities required to safeguard the use of AI, from container to model
We’ll focus on practical architecture and operational controls for AI workloads, especially when they are built from open-source code, exposed to user input, run in containers, and make privileged decisions. We will explore how AI deployments deserve the same baseline protections we already apply to modern applications, plus AI-specific extensions.

Speaker

Tsvi Korren

Tsvi Korren

Field CTO - Aqua Security

Tsvi Korren has been an IT security professional for over 25 years. In previous positions at DEC and CA Inc., he consulted with various industry verticals on the process and organizational aspects of security. As the Field CTO at Aqua, he is tasked with delivering commercial and open source solutions that make Cloud Native workloads the most secure, compliant and resilient application delivery platform.